DigiCert 是全球首屈一指的數位憑證領導廠商,針對新興的物聯網(IoT)市場,提供值得信賴的 SSL 憑證、私人託管的 PKI 部署,以及裝置憑證。創立至今近 15 年間,DigiCert 始終以超越極限做為進步的動力,改良網路認證方式。
EV Code Signing
延伸驗證(Extended Validation) 程式碼簽章憑證
延伸驗證(EV)程式碼簽章憑證囊括所有數位簽章程式碼的優點,另外加上嚴格的檢查過程及硬體安全要求,讓使用者更信任您的應用程式。
EV 程式碼簽章提供下列功能:
雙重認證
購買憑證後將收到一個 USB 隨身碟,其中儲存著包含私鑰的加密 token。只有握有實體裝置者,方可使用 EV 程式碼簽章憑證來簽署程式碼,以此強化認證與安全性。
時效性簽章
增加選配的時間戳記,讓您的簽章在原始 EV 程式碼簽章憑證過期後,不會因而消失。若是沒有時間戳記,您的簽章會隨著憑證過期而失效,必須重新簽署個人程式碼。
自動提升 Smartscreen® 信譽
Microsoft SmartScreen® 應用程式信譽(Application Reputation)篩選工具可減少警告訊息,以提升品牌信譽和終端使用者的信任感。
支援硬體安全模組(HSM)
EV 程式碼簽章憑證可安裝於硬體安全模組,讓您更能夠掌控自己的憑證和相關私鑰。您的組織中,任何有權存取硬體安全模組者,都可以使用儲存在其中的憑證來簽署程式碼。
相容於通用平台
無需重新頒發憑證即可簽署 (如 Authenticode、 Kernel Mode 等)其他平台的程式碼。
版本比較
Code Signing 程式碼簽章憑證 |
EV Code Signing EV程式碼簽章 |
|
經過加密數位簽章 | V | V |
需要使用硬體令牌進行雙因素身份驗證 | V | |
使用Microsoft Smartscreen Filter 立即獲得聲譽 | V | |
需要使用硬體令牌進行雙因素身份驗證 |
技術規格
Microsoft Authenticode®
Microsoft Office & Microsoft VBA
Microsoft Kernel-Mode Code Signing
Adobe® AIR®
Java®
Mozilla® Objects
SSL Certificate
數位憑證是網路安全的主幹。
安全通訊協定(SSL)憑證(有時稱為數位憑證)可為瀏覽器或電腦和伺服器或網路之間建立加密連結。在每次會話時(session)時,SSL 連結可保護信用卡資訊等交換機密資料不會遭到非授權方攔截。
創建安全連接
SSL 是建立加密連結的標準安全技術 — 以下是它的運作原理。
有一種終端使用者看不見的程序叫做「SSL 握手」(SSL handshake),可在網路伺服器和瀏覽器之間創造安全連結。它以三把金鑰打造一個對稱式會話金鑰,再以此加密所有傳輸資料。
- 伺服器傳送自己的對稱式公開金鑰發送給瀏覽器。
- 瀏覽器創造一個對稱會話金鑰,並以伺服器的對稱式公開金鑰加密,然後發送給伺服器。
- 伺服器用自己的對稱式私密金鑰解密加密的會話金鑰,以便取得對稱式會話金鑰。
- 伺服器和瀏覽器現在都以對稱式會話金鑰加密並解密所有傳輸的資料。這個程序可以保障通道安全,因為只有這對瀏覽器和伺服器知道它們的對稱式會話金鑰,而這組會話金鑰只可用於這一段會話。若是瀏覽器隔日再連接同一部伺服器,則需要再產生一副新的會話金鑰。
為您的網站訪問者和企業建立信任和在線安全性
- Encrypt sensitive data
- Activate HTTPS and the lock icon
- Comply with PCI standards
- Prove legitimacy
- Strengthen brand identity
- Increase SEO rank
Basic TLS/SSL Certificates
系統需求
Technical Specifications
- Standard X.509 certificates
- Symmetric 256-bit encryption
- RSA public-key SHA-2 algorithm (supports hash functions: 256, 384, 512)
- ECC public-key cryptography (supports hash functions: 256 and 384)
- Unlimited server licensing
- Supports 2048-bit public key encryption (3072-bit and 4096-bit available)
版本比較
Standard SSL | EV SSL | Multi-Domain | Wildcard SSL | Secure SiteTM Business Certificate | |
Award-winning customer support | V | V | V | V | V Priority support and validation |
Compatible with all major browsers and mobile devices |
V | V | V | V | V |
Secures both example.com and www.example.com |
V | V | V | V | |
Highest authentication plus brand protection |
V | V | |||
Warranty | $1 million | $1 million | $1 million | $1 million | $1.75 million |
Secures unlimited subdomains | V | V | |||
EV option available | V | V | |||
Wildcard SAN option available for additional cost |
V | V |
Business TLS/SSL Certificates
Norton Secured™ seal
Improve conversion rates with the Norton Secured seal, proven to be the most well-recognized symbol for online security.
Priority Support
Exclusively for DigiCert Secure Site customers, reach our experts any day at any time with a dedicated concierge phone line, and 24/7/365 email and live chat.
Priority Validation
Skip the queue. DigiCert Secure Site customers get exclusive rights to and get the fastest validation experience available.
Million Warranty
In the event a certificate-related failure causes your customer damage or financial loss, you’ll be covered by a relying-party warranty.
DigiCert CertCentral
The best certificate demands the best platform. Management from installation to renewal, with tools to discover and analyze all your certificates across your networks.
系統需求
Technical Specifications
- X.509 format Certificate meets software & industry standards
- Symmetric 256-bit encryption
- Unlimited server licensing
- Supports 2048-bit public key encryption (3072-bit and 4096-bit available)
- Free reissues and replacements for the lifetime of the certificate
版本比較
SINGLE DOMAIN | MULTIPLE DOMAINS | SUBDOMAINS | |||
SECURE SITE SSL | SECURE SITE EV SSL | SECURE SITE MULTI-DOMAIN |
SECURE SITE EV MULTI-DOMAIN | SECURE SITE WILDCARD | |
NUMBER OF DOMAINS SECURED |
1 (secures both example.com and www.example.com) |
1 (secures both example.com and www.example.com) |
4 fully qualified domain names (FQDN) | 3 fully qualified domain names(FQDN) | All subdomains for a single domain |
The Internet's most-recognized trust mark | V | V | V | V | V |
Exclusive priority support and validation | V | V | V | V | V |
DigiCert CertCentral account, the most comprehensive certificate management platform on the market |
V | V | V | V | V |
Access to a malware checker with 70+ antivirus scanners and URL/domain blacklist services for quick malware checks | V | V | V | V | V |
Compatible with all major browsers and mobile devices |
V | V | V | V | V |
Vulnerability Assessments help you identify and take action against critical weaknesses on your website | V | ||||
RSA public-key SHA-2 algorithm (supports hash functions: 256, 384, 512) |
V | V | V | V | V |
ECC public-key cryptography (supports hash functions: 256 and 384) |
V | V | V | V | V |
Warranty | $1.75 million | $1.75 million | $1.75 million | $1.75 million | $1.75 million |
Highest authentication plus brand protection | V | V |
Code Signing Certificates
Protect users from downloading compromised software,
prevent tampering, and provide the trusted assurance of
authentication by using a digital signature.
Code Signing Certificates are used by software developers to digitally sign apps, drivers, and software programs as a way for end-users to verify that the code they receive has not been altered or compromised by a third party. They include your signature, your company’s name, and if desired, a timestamp.
Code Signing Certificates ensure that users won’t receive a warning message at installation or start-up and are ideal for securing:
Document Signing Certificates
Improve security, increase the speed of business, and securely sign documents in Adobe, Microsoft, and other programs.
Secure, Authenticated Signatures with a Single Click
Document Signing certificates allow individuals, teams, and organizations to add an electronic, digital signature to a document in a variety of file formats to prove ownership. The digital signature is an encrypted hash of your message that can only be decrypted by someone who has a copy of your public key, which ensures:
- Document stays unchanged
- Sender's identity confirmed
- Sensitive information protected
Client Certificates
Prove identity and digitally sign or encrypt email
communications using these highly versatile certificates.
Client certificates, also called personal ID certificates,are used to verify identity for an individual.
- Allows access to specific applications, websites, or interfaces, as well as devices like laptops and cellphones
- Digitally signs and encrypts email using the S/MIME protocol, which verifies the sender and even prevents tampering
- Provides enhanced security measures in case usernames and passwords are misplaced or stolen
FBCA Certificates & Direct Messaging
Gain the ability to transfer records to federal agencies and fortify your entire network for Direct messaging exchange.
Any organization exchanging healthcare information with a federal agency must use certificates cross-signed by the Federal Bridge Certification Authority (FBCA). All of our FBCA certificates are trusted by federal agencies and guarantee interoperability, allowing you to safely exchange messages.
Increase Identity Assurance with FBCA or NIST LoA 3 Certificates
Meet compliance standards to correspond with U.S. federal agencies
and gain the ability to issue Electronic Prescriptions of Controlled Substances (EPCS).
Both FBCA and NIST LoA 3 are established standards. Digital signatures in these types of certificates show an end-user that the identity of the individual named in the certificate is verified and is trustworthy. We can help you with multiple levels of assurance, including FBCA Basic, FBCA Medium, and NIST LoA 3.
What is Direct Messaging for Healthcare?
Direct messaging is the national encryption standard for sending healthcare records over the internet. It allows Health Information Service Providers (HISPs) across the U.S. to exchange patient records securely and mitigate risks that come from transferring records over unprotected channels, like traditional email.
- Stronger security for patient data
- Guards PHI
- Streamlined standards for providers
- Improves workflows
- Enhances communication
Wi-Fi Certificates
Increase trust in public hotspots, protect user data, and streamline the registration process using Wi-Fi Alliance-approved OSU certificates.
A Wi-Fi Certificate protects the registration process and encrypts log-in credentials when connecting to public Wi-Fi, ultimately providing secure network access and increasing trust in public hotspots and sign-up services.
- Authenticates sign-up service providers
- Encrypts user data during the sign-up process and communication between a mobile device and OSU server
- Ensures that a user is communicating with the intended
- service provider
Custom Certificate Profiles
Work with experienced PKI engineers to develop templates for every certificate type specific to your cloud-based PKI.
Certificate profiles define every parameter associated with a specific certificate. Issuing CAs use profiles customized to each organization based on their expected use and anticipated security concerns.
- Authentication method
- Certificate defaults
- Profile constraints
- Certificate outputs
Device Certificates
Verify identity, encrypt communications, and protect home networks for all your internet-connected devices before and after manufacturing.
What are Device Certificates?
Proper authentication and encryption are a critical component of securing connected devices.
A device certificate creates an identity for each “thing” in an IoT ecosystem, making sure each device authenticates as it connects, and protects communication between devices.
Why Device Communications Need Protection
Certificates mitigate risk for users and safeguard systems.
With thousands of unsecured devices connecting to the internet each day, private data communicated between devices are a prime attack point for hackers. Properly implemented, a Public Key Infrastructure (PKI) security solution provides strong device identity and encryption for in-transit data, and protects devices and networks from exploits.